HomeinetESET discovered Hesperbot, a new smart malware

ESET discovers Hesperbot, a new smart malware

A new powerful malware designed to attack banks has been spotted circulating in Europe. Hesperbot targets victims from Europe as mentioned above and attempts to steal bank log-ins using common techniques such as keystroke logging, screenshots , and videos from the victim's computer screens.

security card

The malware trojan is similar to the infamous Zeus and SpyEye banking malware, but according to ESET, the security firm that discovered it, it is completely new. And although it has so far hit a few hundred computers in Europe – mainly in Turkey, Portugal, the Czech Republic and the UK – it could easily be the start of a wider malware that could spread to the rest of the world.

"We believe that the people behind this are probably preparing for wider deployment," Stephen Cobb, a security researcher at ESET, in a phone interview with Mashable . "It's something we've seen before. It first rolls out in lesser-known countries and then moves on to larger markets."

It's like beta-testing for cybercriminals. Criminals test the malware's functionality in smaller countries, fix it, and then give it to larger targets, Cobb explained.

The possibilities of malware are many, but its goal is the same: stealing data to make money.

“The attackers’ goal is to obtain the victim’s credentials, and through them access to their bank account. Typically, the malware comes with an application that contains it on Symbian, Blackberry or Android,” says Robert Lipovský, a malware researcher at ESET.

The malware first attacks the victim's computer. Once the victim's computer is infected, a malicious website asks the user to enter their mobile phone number and model number, and then sends them a text message containing a link to a malicious mobile app that, if installed, infects the phone and monitors all data in order to discover and bypass banks' two-factor authentication.

Hesperbot spreads via high-quality phishing emails that appear to come from trusted sources. ESET first discovered it in August, when the criminals behind it began infecting computers in the Czech Republic with emails that appeared to come from the local postal service.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS